| From: | Zsolt Parragi <zsolt(dot)parragi(at)percona(dot)com> |
|---|---|
| To: | Jacob Champion <jacob(dot)champion(at)enterprisedb(dot)com> |
| Cc: | Nikolay Shaplov <dhyan(at)nataraj(dot)su>, Álvaro Herrera <alvherre(at)kurilemu(dot)de>, VASUKI M <vasukianand0119(at)gmail(dot)com>, PostgreSQL Hackers <pgsql-hackers(at)lists(dot)postgresql(dot)org>, david(dot)g(dot)johnston(at)gmail(dot)com, Robert Haas <robertmhaas(at)gmail(dot)com>, myon(at)debian(dot)org |
| Subject: | Re: Custom oauth validator options |
| Date: | 2026-10-10 10:12:35 |
| Message-ID: | CAN4CZFOZX7r4-i--ucw38mhb6z0WzC1U+VFt45mFwiw5qqqbXg@mail.gmail.com |
| Views: | Whole Thread | Raw Message | Download mbox | Resend email |
| Thread: | |
| Lists: | pgsql-hackers |
Claude pointed out that pg_hba_file_rules leaves the validator options out:
host all all 127.0.0.1/32 oauth issuer="https://issuer.example"
scope="pg" validator.log="hi" validator.typo=1
SELECT options FROM pg_hba_file_rules WHERE line_number = 2;
options
-----------------------------------------------------------
{issuer=https://issuer.example,scope=pg,validator=validator}
I think this matters a bit more than for the builtin options, because
unknown validator.* names can't be detected at reload time, and the
view is the only place where an admin can see what the server actually
parsed. The values still won't go through validations, e.g. in the
above example typo will be simply displayed, but I think that's
already better than hiding them and is worth doing.
The attached patch emits them as validator.<name>=<value>, in the
order they appear on the line. Since there's no limit on how many
options a line can have, the fixed MAX_HBA_OPTIONS array doesn't work
anymore, so options are sized dynamically now (MAX_HBA_OPTIONS plus
the number of validator options).
| Attachment | Content-Type | Size |
|---|---|---|
| v1-0001-oauth-Show-validator.-options-in-pg_hba_file_rule.patch | application/octet-stream | 3.4 KB |
| From | Date | Subject | |
|---|---|---|---|
| Next Message | Srinath Reddy Sadipiralla | 2026-10-10 10:44:52 | [RFC PATCH v1] On-demand WAL replay: accept connections before crash recovery has applied the WAL |
| Previous Message | Vadim Ponomarev | 2026-10-10 10:02:29 | Re: Reduce SyncRepLock contention on the commit path |